CVE Details
Basic Information
| Title | Portabilis i-Educar Calendar Module educar_calendario_dia_motivo_cad.php cross site scripting |
|---|---|
| Type | cve |
| Published | 2025-07-20T04:32:05.817Z |
| Modified | 2025-07-20T04:32:05.817Z |
Product Information
| Vendor | Portabilis |
|---|---|
| Product | i-Educar |
| Version | 2.9.0 |
CVSS Information
| Base Score | 5.1 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P |
Affected Products
- Portabilis i-Educar 2.9.0
Additional Information
| CWE List | CWE-79, CWE-94 |
|---|---|
| Source | VulDB |
Description
A vulnerability classified as problematic was found in Portabilis i-Educar 2.9.0. Affected by this vulnerability is an unknown functionality of the file /intranet/educar_calendario_dia_motivo_cad.php of the component Calendar Module. The manipulation of the argument Motivo leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.